Encrypted file sharing
Protect sensitive files in transit and at rest while keeping access tied to the intended users.
Encryption matters, but a secure exchange also needs identity, permissions, expiry and evidence. My MX Data keeps those controls together around the file handoff.
Encryption is stronger when the surrounding workflow is controlled too.
AES-256 protection
Protect data during transfer and while held within the service.
Named-user access
Keep availability associated with known recipients instead of anonymous links.
Audit trail and expiry
Retain evidence and revisit access when the business purpose ends.
ASR in motion
Protection that separates and restores
Identifiable information is anonymised, remaining data is distributed as separate secure shards, and the original file is restored from those fragments.
Trusted for sensitive, accountable file exchange.
Frequently asked questions
Clear answers about Encrypted File Sharing.
What is encrypted file sharing?
Encrypted file sharing is the exchange of files using cryptographic protection so information is not left exposed during relevant stages of storage or transfer. For business use, encryption is most useful when it sits alongside controls that determine who should receive a file, how long access lasts and what evidence is retained afterwards.
My MX Data uses AES-256 encryption as one part of a wider security model. MX can combine it with named-recipient access, permissions, multi-factor authentication, expiry settings and detailed activity records. That gives organisations protection around both the data itself and the way the exchange is managed.
For highly sensitive information, MX also offers ASR, a separate patented methodology that anonymises data, separates it into protected shards and restores it for an authorised recipient. ASR should not be treated as another name for encryption.
How does My MX Data control who can access shared files?
Encryption protects the information, but it does not decide who should receive it. MX therefore combines encryption with named-recipient and permission-based access, helping organisations restrict an exchange to approved people rather than relying on an unrestricted public link.
Multi-factor authentication can add another identity check before access is granted, while expiry settings and download conditions can limit what happens after a file is sent. The combination matters because a strongly encrypted file can still be mishandled if access is poorly controlled.
You can explore the wider access, administration and monitoring controls in the MX features overview. That distinction matters when confidential material is being shared repeatedly with clients, suppliers or advisers.
Can MX handle very large files?
Yes. MX supports very large file transfers without arbitrary file-size restrictions, so encryption and controlled recipient access do not have to be abandoned simply because a file is too large for email or another transfer service.
This is useful for CAD data, high-resolution media, software packages, engineering files and large document sets. Keeping large transfers inside the same controlled workflow can reduce the temptation to split files into several parts or move them through an unapproved service. Our large-file sharing page explains the use case further.
What activity can administrators and senders see?
Authorised administrators and relevant senders can review activity associated with an encrypted exchange. Depending on the transaction, MX may record uploads, access, downloads, comments, timestamps, recipient activity, user information, transaction history and relevant IP details.
That record answers practical questions that encryption by itself cannot. A sender can check whether the intended recipient has accessed a file, see whether a download is still pending and review the history if an exchange is later questioned. For recurring external sharing, this can remove a surprising amount of guesswork.
Activity records also support internal reviews and compliance work by providing evidence of how information moved through the exchange. They do not prove that every wider policy or legal requirement has been met, but they give the organisation a much clearer factual record to work from.
Our article on file audit trails and modern compliance looks at this evidence in more detail. For organisations with formal assurance processes, this evidence can also help security or compliance teams reconstruct a transaction without depending on screenshots or forwarded messages. It gives them timestamps and recipient activity in one place.
How are files protected during an exchange?
MX uses AES-256 encryption as part of its security controls, but protection does not stop there. Named recipients, permissions, multi-factor authentication, expiry settings and audit records help control the exchange around the encrypted data.
For organisations handling particularly sensitive or commercially valuable information, MX can also use ASR, which stands for Anonymise, Shard and Restore. The process transforms the data so the underlying content is not recognisable, separates it into protected shards and restores the information for an authorised recipient. ASR is an additional method rather than a replacement name for encryption.
The result is a layered approach in which data protection, identity, access and evidence all contribute to the security of the exchange. It also means teams can keep familiar operational controls around sensitive exchanges instead of treating encryption as a separate technical step.
How is MX different from email attachments or public sharing links?
An email attachment can leave the sender with limited control once it reaches another inbox, while a public sharing link may be forwarded beyond the original audience. Encryption helps with confidentiality, but business teams often need greater certainty about who is authorised to receive the file and what happened afterwards.
MX combines encrypted transfer with named-recipient access, configurable permissions, expiry settings and audit records. This keeps more of the exchange connected, including recipient activity and relevant communication, instead of relying on separate email threads and open links.
Email and mainstream cloud tools still have valid uses. Where the task is a sensitive handoff that needs clearer identity and traceability, a controlled secure file-sending workflow may be a better fit. This can be particularly useful where the sender is accountable for confidential information after it crosses the organisation boundary.
Can access expire or be restricted after a file is sent?
Yes. Encrypted files do not need to remain available indefinitely. MX supports expiry settings that can limit the period in which a recipient is able to access an exchange, helping organisations match availability to the actual business need.
Named recipients, permissions and relevant download conditions can add further restrictions. These controls are especially useful for confidential documents, financial information or intellectual property where the sender wants the protection to extend beyond the moment the file is transmitted. This is useful when access should end automatically after a review or delivery window.
Is encryption the only security control in MX?
No. Encryption is important, but MX treats it as one part of a broader security model. AES-256 encryption helps protect information during relevant stages of storage and transfer, while named-recipient access, permissions and multi-factor authentication address who is allowed to reach it.
Expiry settings can reduce the period in which a file remains available, and audit records provide evidence of access, downloads and other activity. For especially sensitive data, MX can also use ASR, which anonymises information, separates it into protected shards and restores it for an authorised recipient.
Security is therefore spread across data protection, identity, access, availability and oversight. Our article on MX security features for data sharing gives a broader view of those controls. Controls can also vary with sensitivity, so routine files need not be handled in the same way as highly confidential material.